Skip to content
Certopact certopact
← Articles Identity verification

Aadhaar OTP verification explained (AUA / KUA)

19 Jun 2026 7 min read

Online Aadhaar verification is the most familiar way to confirm identity in India: the resident approves a one-time password, and UIDAI confirms the match. It sounds simple, but the details — who you go through, what you get back, and what is and isn't stored — decide whether your check is both authoritative and compliant.

What AUA and KUA mean

You don't talk to UIDAI directly. You go through a licensed agency: an Authentication User Agency (AUA) for yes/no authentication, or an e-KYC User Agency (KUA) when you also need verified identity attributes back. Many providers, Certopact included, operate as a Sub-AUA so organisations can verify without holding a UIDAI licence themselves.

How the OTP flow works, step by step

  • The visitor provides their Aadhaar number with consent.
  • UIDAI sends a one-time password to the resident's registered mobile.
  • The visitor enters the OTP to approve the check.
  • UIDAI returns the result — a yes/no match, and for e-KYC a signed set of attributes (name, photo, demographics).
  • Certopact runs name-match scoring and can add a Live Face check against the returned photo.

What you get back

For plain authentication you get a definitive yes/no from UIDAI. For e-KYC you also receive a digitally signed bundle of attributes you can trust — typically the name, photo and demographic fields — straight from UIDAI's records, not transcribed from a document.

Consent and privacy

Consent is captured per transaction, and done properly the full Aadhaar number is never stored — only the result and the attributes you actually need, purpose-limited to the visit or onboarding. That aligns with the DPDP Act; confirm your specific obligations before deployment.

When OTP works — and when it doesn't

Online OTP is the most authoritative, real-time check — ideal where you have connectivity and the resident has their registered mobile to hand, such as a corporate reception or an online onboarding flow. Where connectivity or OTP delivery is unreliable — plant gates, remote sites, high-throughput entrances — use offline OVSE instead. See online vs offline for the full comparison.

Where Aadhaar OTP verification is used

Online OTP underpins a lot of everyday checks: onboarding customers in BFSI / NBFC KYC, verifying guests at corporate receptions with reliable connectivity, and confirming staff or member identity inside apps. Wherever the resident has their registered mobile and you have a connection, it is the quickest authoritative check — and you can fall back to offline OVSE where those conditions don't hold.

Aadhaar OTP in Certopact Entry

Certopact Entry runs online AUA/KUA verification alongside offline OVSE from one engine, with DigiLocker, name-match scoring, Live Face and Restricted Visitor screening — configurable per location. Learn more about Aadhaar visitor verification. This is general information, not legal advice.

Stay in touch

Get a heads-up on new articles, customer stories and events from Certopact.

See Certopact verify a visitor in minutes.

Book a 30-minute demo. We'll walk through Entry, Access and offline verification on your use case.